What isn't secure about Tails? Its been recommended by so many InfoSec podcasts that I've been poking around in it on a USB stick
I've commented in this thread that at one point, such a vulnerability was left unpatched in Tails for years despite being documented and a PoC existing.
Whonix on the other uses two VMs, one of which runs Tor and the other applications, and connects via an internal network. This means that non-Tor connections are impossible, as the VM where you run software is completely unaware of the real, external IP.
This raises the level of exploit needed substantially, from user to root, to remote kernel exploits or hypervisor escapes.